NEW
Font size
WorksheetsCISA 2.7.24
Total questions: 8
Worksheet time: 12mins
When an intrusion into an organization's network is detected, which of the following should be done FIRST?
Contact law enforcement.
Identify nodes that have been compromised.
Block all compromised network nodes.
Notify senior management
Which of the following is an audit reviewer's PRIMARY role with regard to evidence?
Ensuring appropriate statistical sampling methods were used
Ensuring evidence is labeled to show it was obtained from an approved source
Ensuring unauthorized individuals do not tamper with evidence after it has been captured
Ensuring evidence is sufficient to support audit conclusions
Which of the following would be MOST useful to an IS auditor assessing the effectiveness of IT resource planning?
Budget execution status
A capacity analysis of IT operations
A succession plan for key IT personnel
A list of new applications to be implemented
Which of the following MOST effectively minimizes downtime during system conversions?
Phased approach
Parallel run
Direct cutover
Pilot study
Which of the following is the MOST important reason for IS auditors to perform post-implementation reviews for critical IT projects?
To determine whether vendors should be paid for project deliverables
To provide the audit committee with an assessment of project team performance
To provide guidance on the financial return on investment (ROI) of projects
To determine whether the organization's objectives were met as expected
Which of the following is the PRIMARY role of the IS auditor in an organization's information classification process?
Securing information assets in accordance with the classification assigned
Validating that assets are protected according to assigned classification
Ensuring classification levels align with regulatory guidelines
Defining classification levels for information assets within the organization
Management receives information indicating a high level of risk associated with potential flooding near the organization's data center with in the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?
Risk reduction
Risk acceptance
Risk transfer
Risk avoidance
After an employee termination, a network account was removed, but the application account remained active. To keep this issue from recurring, which of the following is the BEST recommendation?
Integrate application accounts with network single sign-on.
Perform periodic access reviews.
Retrain system administration staff.
Leverage shared accounts for the application.
